CVE-2023-42663: Apache Airflow: Bypass permission verification to view task instances of other dags

Post Reply
Shane1145
Posts: 1854
Joined: Wed Sep 25, 2024 2:31 pm

CVE-2023-42663: Apache Airflow: Bypass permission verification to view task instances of other dags

Post by Shane1145 »

The vulnerability "CVE-2023-42663: Apache Airflow: Bypass permission verification to view task instances of other DAGs" allows unauthorized users to bypass access controls and view task details across different DAGs. This can lead to unauthorized data access and potential exposure of sensitive information within Apache Airflow workflows.

https://hackerone.com/reports/2208656
Post Reply